CVE-2026-1434
Received Received - Intake
Reflected XSS in Omega-PSIR lang Parameter Enables Script Execution

Publication date: 2026-02-27

Last updated on: 2026-02-27

Assigner: CERT.PL

Description
Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victim’s browser. This issue was fixed in 4.6.7.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-27
Last Modified
2026-02-27
Generated
2026-06-16
AI Q&A
2026-02-27
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
pw omega-psir From 4.5.9 (inc) to 4.6.7 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

Omega-PSIR is vulnerable to a Reflected Cross-Site Scripting (XSS) attack via the lang parameter.

An attacker can create a malicious URL that, when a victim opens it, causes arbitrary JavaScript code to execute in the victim's browser.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary JavaScript in the context of the victim's browser.

Such execution can lead to theft of sensitive information, session hijacking, or performing actions on behalf of the victim without their consent.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

The vulnerability in Omega-PSIR related to Reflected XSS via the lang parameter was fixed in version 4.6.7.

To mitigate this vulnerability, you should immediately upgrade Omega-PSIR to version 4.6.7 or later.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1434. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart